Vulnerability record · CVE-2013-5704 · published 15 April 2014
CVE-2013-5704: Apache HTTP Server mod_headers RequestHeader unset bypass via chunked trailers
Apache · Http Server
The mod_headers module in Apache HTTP Server 2.2.22 fails to apply "RequestHeader unset" directives to headers placed in the trailer portion of a chunked transfer-coded request. This lets a remote client smuggle a header past configuration intended to strip it, undermining header-based access controls or input filtering. The vendor disputes this is a security issue in httpd itself.
Description
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
AV:N/AC:L/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw is remotely reachable without authentication and has high EPSS, but impact is limited to bypassing header-stripping directives and the vendor disputes its security severity.
What it is
The mod_headers module in Apache HTTP Server 2.2.22 fails to apply "RequestHeader unset" directives to headers placed in the trailer portion of a chunked transfer-coded request. This lets a remote client smuggle a header past configuration intended to strip it, undermining header-based access controls or input filtering. The vendor disputes this is a security issue in httpd itself.
Impact
An attacker can reintroduce a header that administrators explicitly configured to be removed, potentially bypassing header-based authorization, filtering, or routing rules. The direct gain depends entirely on what downstream logic trusts that header; the record does not specify a concrete privilege escalation or data compromise.
Attack surface
Reachable over the network by sending an HTTP request with chunked transfer coding and a crafted trailer header; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N. The flaw is in request parsing and header handling, not in a client-side component.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.56 (99th percentile), and one reference is tagged as an exploit write-up. No ransomware usage is documented.
What to do
- Upgrade Apache HTTP Server to a release that includes the mod_headers trailer handling fix; check vendor errata (Red Hat, Ubuntu, Oracle, Apple) for the applicable patched build.
- If immediate upgrade is not possible, disable or restrict chunked transfer coding at the reverse proxy or load balancer for untrusted clients.
- Do not rely solely on RequestHeader unset for security-critical header stripping; enforce header allow-lists at the edge proxy instead.
- Review downstream applications that trust headers such as X-Forwarded-For or authorization headers for exposure to smuggled trailer values.
Detection
- Log and alert on HTTP requests containing trailer headers, especially those with chunked transfer coding and non-empty trailer sections.
- Monitor for requests where a header configured for removal via RequestHeader unset appears in the trailer rather than the main header block.
- Correlate proxy and origin logs for discrepancies in header sets between the edge and the backend server.
- Watch for repeated chunked requests from a single source that target endpoints protected by header-based access rules.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-5704 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-5704), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.